asc-beta-review

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly fit its stated App Store Connect beta-review purpose, but it relies on an unspecified external asc CLI that appears to be a non-Apple third-party tool and forwards sensitive App Store Connect credentials and possible demo-account secrets into it. No overt exfiltration or unrelated access is shown, so this is not confirmed malicious, but install/provenance ambiguity and credential forwarding make it medium risk.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:22 AM
Package URL
pkg:socket/skills-sh/tddworks%2Fasc-cli-skills%2Fasc-beta-review%2F@c04f79c673116995ed010c9b4eccc9c3960156ad